OpenClaw skills. macOS. Linux. Windows. Node.js 20+. Runs on your machine.

Scan OpenClaw skills before you trust them.

A skill is markdown that tells your agent what to do, and attackers hide installers and credential grabs inside it. Ironheights reads skill files as data, flags risky patterns with fixed rules, can fetch a ClawHub skill and install it only if the scan is clean, and tells you when an installed skill or agent file changes. It never runs what it scans, makes no network call during a scan, and sends no telemetry.

Free and open source under Apache-2.0. Version 0.3.0 on npm with a provenance signature. No findings means the rules did not match, not that a skill is safe. See what is new in 0.3.0.

Quick answerLast updated

What is Ironheights?

Ironheights is a free, open-source (Apache-2.0) command-line scanner for OpenClaw agent skills. It reads skill files as data, checks them against 35 published rules, and reports changes against a local baseline. Version 0.3.0 can also fetch a skill and install it only if the scan is clean. No findings means no rule matched; it is not proof of safety.

All facts, with sources

Install only from the official sources. Fake “security” skills are a known lure.

npm: ironheightsGitHub releasesironheights.dev

The problem

Skills are an attack surface, and the payload is often plain text.

Markdown as installer

A “prerequisite” line tells the agent to download and run a script. There may be no malware file for a classic scanner to find.

Real campaigns

Koi Security reported 341 malicious skills in its ClawHavoc audit. Snyk’s ToxicSkills study confirmed 76 malicious payloads in 3,984 skills.

Scanning at upload is not the end

Marketplace checks help, but they run before install. Files on your machine can still change after you trusted them.

New in 0.3.0

Runs next to the security tools you already have.

Most agents that care about security already run another scanner or guard. Ironheights now finds them, shows where the two would collide, and keeps its own guard from blocking over them. It reads files only and changes nothing.

Read-only

Works next to your other security tools

Find the other scanners and guards already on your agent, and see where they overlap with Ironheights.

It reads your OpenClaw config (plugin and hook entries), plugin manifests, skill and hook folders, known state folders, PATH, and CI or pre-commit files in a project. Each tool it lists shows the file that gave it away.

Where it stops: Heuristic: a renamed or unlisted tool is not found.

Not a sandbox

A guard that shares the hook

Run the guard beside another guard without a surprise about who blocks.

Set plugins.entries.ironheights-guard.config.priority to an integer from -1000 to 1000. Higher runs first, and OpenClaw's own default is 0.

Where it stops: Sets the order only. Not a sandbox.

No allowlist by name

Security tools are not trusted by name

Read another security skill's findings with less noise, and without giving a fake a free pass.

The note reads: name match only, not verified. Anyone can copy a name.

Where it stops: A name proves nothing; the verdict does not change.

Ask your own machine, not a guess.

One command lists the other security tools it can see, with the file that showed each one, then the overlaps worth fixing and how. The example is real output from a test machine, trimmed.

Where it stops: detection is heuristic. A tool it does not list, or one that was renamed, is not found, and a name can be copied. No findings is not proof that tools will not interfere.

npx ironheights coexist
Ironheights coexistence check (read-only, offline, heuristic)
Ironheights guard: plugin enabled, mode enforce (plugin config), priority 80

Other security tools detected: 3
  - clawdefender [skill-scanner] present, medium confidence
      skill-dir: skill folder clawdefender in managed skills
  - guard-scanner [runtime-guard] enabled, high confidence, mode enforce (default), guards tool calls
      plugin-config: plugins.entries.guard-scanner
  - skill-vetter [instruction-skill] present, medium confidence
      skill-dir: skill folder skill-vetter in managed skills

Conflicts and notes: 2
  [medium] IH-COEX-001 More than one tool-call guard is active
    fix: Pick one tool to own blocking. Keep Ironheights in monitor mode
         (the default) if the other guard enforces.
  [low] IH-COEX-008 Several skills tell the agent to scan or vet installs
    fix: Decide which verdict wins. A deterministic result such as
         `ironheights safe-install` should outrank a checklist the model applies.

Detection is heuristic. A name can be copied. A tool we do not list, or one
that was renamed, is not found. Absence of findings is not proof that tools
will not interfere.

New in 0.2.0

Protection beyond scanning.

The 0.2.0 release added checks before you install a skill, while your agent runs, and after something changes. Each one says what it does and where it stops.

Most useful first

Fetch and safe-install

Scan a ClawHub skill before it ever reaches your agent, and install it only when the scan is clean.

Nothing that is downloaded is executed. Files are written readable only by you (mode 0600) and archives are never extracted.

npx ironheights safe-install <owner>/<slug>

Where it stops: A clean verdict is not proof of safety.

Signed advisory feed support

Match a skill against a signed list of known-bad skills, offline, before you trust it.

The feed is checked with an Ed25519 signature. A bad signature is rejected and never cached.

Where it stops: Feed not published yet; a skill missing from a feed is not proof it is harmless.

Signed baselines

Notice when someone edits your saved baseline to hide a change.

Sign with an HMAC-SHA256 or an Ed25519 key file. Ironheights does not create or store the key for you, and on macOS and Linux it refuses a key file that other users can read.

npx ironheights verify --key <file>

Where it stops: Keep the key private; an attacker with your key can re-sign.

Not a sandbox

Guard plugin for agent tool calls

See when an agent reads credentials, runs a download-and-execute command, or contacts an unknown host.

Credential reads: SSH, cloud and wallet folders, private keys, .env files, and OpenClaw credentials.

npx ironheights guard status

Where it stops: Not a sandbox. Monitor mode only logs. A compromised skill that can edit your config can turn it off.

A to F trust grade

Read the result in one glance, and paste it in your README.

A is 90 to 100, B 80 to 89, C 70 to 79, D 60 to 69, and F 0 to 59.

Where it stops: A good grade is not a safety rating.

Honest incomplete verdicts

A scan that did not look everywhere says so, instead of reporting clean.

dist/ is scanned like any other folder, so a pipe-to-shell line there is a finding.

Where it stops: Skipped files and folders are still not checked.

Piped JSON that stays whole

scan --json | jq now works on big reports.

Applies to scan --json, scan --format html, and every other command that writes to stdout.

Where it stops: A bug fix, not a new detection.

Try it on the next skill you install.

One command downloads a ClawHub skill, scans it, and installs it only when the scan is clean. Nothing is executed along the way. No findings still does not mean a skill is safe, so read what you install.

npx ironheights safe-install <owner>/<slug>

The foundation

A scanner, a baseline, and a quarantine. Local by default.

01

Scan before you install

Point ironheights scan at a skill folder. Findings are grouped by skill with a rule id, file and line, the matching evidence, and a fix. Output as text, JSON, SARIF 2.1.0, Markdown, or one HTML file, with an A to F grade.

02

35 published rules

Remote shells, prerequisite installs from URLs, undeclared hosts, credential paths, hard-coded secrets, instruction overrides, hidden text, bundled executables, persistence, and integrity changes. See every rule.

03

Integrity baseline

baseline create hashes your skills and agent files. verify reports what was added, modified, removed, or had its mode changed.

04

Quarantine, not delete

quarantine <skill> moves a skill out of the agent’s path. quarantine restore puts it back. Nothing is deleted on its own.

05

Offline by default, no telemetry

Scans stay on the machine. The CLI has no telemetry and no scan makes a network call. Only fetch, safe-install, advisories update, and the optional model review use the network, and only when you run them.

06

Clear verdicts

no-findings, review, block, or incomplete when a file or folder was skipped, with exit codes 0, 1, 2, and 3 so a pipeline can stop on risk.

07

An advisory skill

An optional OpenClaw skill asks the agent to scan first and stop on block. It is a convenience, not the trusted path. The CLI you run yourself is.

How it works

Three commands. Then you decide.

  1. Step 1

    Doctor

    npx ironheights doctor shows which OpenClaw directories it found and whether your Node.js version fits.

  2. Step 2

    Scan

    ironheights scan <path> or --all for every configured skill directory. Read the findings, fix or remove.

  3. Step 3

    Baseline and verify

    Save a baseline once you trust your setup, sign it with --key if you can, then run verify to see anything that changed since.

Read the full walkthrough

Benchmark #1

What a small test of our own shows. In counts, not percentages.

On a 20-skill synthetic corpus written by the Ironheights authors (10 malicious, 10 benign), Ironheights 0.1.0 sent 10 of 10 malicious samples to review, blocked 4 of 10, and flagged 0 of 10 benign samples.

This project

Ironheights 0.1.0

Default config, rules only

Malicious sent to review or block10/10
Malicious blocked4/10
Benign sent to review or block (false alarms)0/10
Compared

Cisco skill-scanner 2.2.2

Rules only (balanced and strict gave identical results); LLM judge off

Malicious sent to review or block4/10
Malicious blocked3/10
Benign sent to review or block (false alarms)0/10
Compared
Code Insight not measured

VirusTotal

Public API, per-skill ZIP uploads

Malicious flagged0/10
Benign flagged (false alarms)0/10

No review or block levels: flagged means any engine said malicious or suspicious.

Each bar has one segment per sample: 10 malicious and 10 benign skills, 20 in all. Ironheights adds up finding scores: 15 or more is review, 80 or more is block.

Pricing

The scanner is free. Paid tiers are still a plan.

Community is free and open source today. Pro and Team are on the roadmap, and the prices below are early hypotheses we are testing with users. Nothing paid is on sale yet.

Open source
Available now

Community

$0 forever
  • Local scanner and integrity monitor
  • Baseline, verify, and quarantine
  • JSON, SARIF, and Markdown output
  • Advisory OpenClaw skill
Planned

Pro

~$12/user/mo
  • Hypothesis, not on sale
  • Credential broker
  • Injection screening
  • Priority signature updates
Planned

Team

~$25/agent/mo
  • Hypothesis, not on sale
  • Fleet inventory and policy templates
  • Audit log and alerts
  • Minimum 5 agents
Apache-2.0No telemetry in the CLINo accountThreat Intel API and Enterprise: planned

Limitations

What Ironheights cannot see.

New and heavily obfuscated attacks

Rules describe known patterns. An attack the rules do not describe will not match.

Runtime-only behavior

The scanner reads files. The optional guard plugin watches a few tool calls from inside the agent. It is not a sandbox, and a quiet log is not proof of safety.

A host that is already compromised

An attacker who can write your home directory can rewrite an unsigned baseline, and can sign a new one if they also have your key.

Read every limitation

FAQ

Questions worth asking a security tool.

A free, open-source command-line scanner and integrity monitor for OpenClaw skills. It flags risky patterns in skill files and reports changes to installed skills and agent files against a baseline you save on your machine.

No. No findings means the rules did not match. Novel, heavily obfuscated, or runtime-only attacks can still get through. Read the skill and treat a clean scan as one signal.

Not during a scan. Scans run locally, there is no telemetry, and no scan makes a network call. Only commands you run on purpose, such as safe-install, advisories update, or the optional model review, use the network. The files it scans are read as data and never executed.

Yes. npx ironheights safe-install owner/slug downloads a ClawHub skill, scans it, and installs it only when the verdict is no-findings. A clean result is not proof of safety, so read what you install.

Run npx ironheights scan with the path to a skill, or install the command globally with npm install -g ironheights. It needs Node.js 20 or newer and runs on macOS, Linux, and Windows. The command is also available as ih.

Only from the ironheights package on npm, the GitHub releases of Frank-Masciopinto/ironheights, or links on ironheights.dev. Copycat “security” skills are a known lure.

Community is free. Pro and Team tiers are planned, and the prices on the pricing page are hypotheses. Nothing paid is on sale yet.

Scan the next skill before your agent reads it.

One command. No account. Nothing leaves your machine.